top of page
perceptive_background_267k.jpg

SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is concatenate…

Published:

2 August 2026 at 22:00:00

Alert date:

3 August 2026 at 15:06:10

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Database & Storage, Zero-Day Vulnerabilities

SiYuan versions before v3.7.3 contain a SQL injection vulnerability in the /api/filetree/searchDocs endpoint. The keyword parameter is directly concatenated into SQL queries without escaping or parameterized binding. The vulnerability is exploitable by users with a publish RoleReader token, or entirely unauthenticated when publish mode is enabled with Publish.Auth.Enable set to false. The underlying SQLite handle is read-write and the driver supports stacked (semicolon-separated) statements, allowing attackers to both read and modify database content. All cleartext (non-encrypted) notebooks on the affected instance are at risk. The fix was introduced in SiYuan v3.7.3. This vulnerability has been documented by NVD, GitHub Security Advisories, and VulnCheck.

Technical details

Mitigation steps:

Affected products:

SiYuan before v3.7.3

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page